The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-79 |
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-79 |
Wed, 02 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry. | |
| Title | CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T10:45:56.333Z
Reserved: 2026-08-25T08:35:51.210Z
Link: CVE-2026-79621
Updated: 2026-09-02T10:11:50.954Z
Status : Received
Published: 2026-09-02T06:17:18.390
Modified: 2026-09-02T11:17:22.030
Link: CVE-2026-79621
No data.
OpenCVE Enrichment
Updated: 2026-09-02T13:30:05Z